Player

I can’t find this backup file. I fuzzed every known file from the enumeration process with every folder I found with a bunch of common extensions. In my desperation I even tried to brute force all possible 3 letter combos on known files.
Could someone give me a hint?

@testmeister said:
I can’t find this backup file. I fuzzed every known file from the enumeration process with every folder I found with a bunch of common extensions. In my desperation I even tried to brute force all possible 3 letter combos on known files.
Could someone give me a hint?

There is an artifact checker on git which definitely help you out. Good Luck :wink:

@MrR3boot got it, thank you!

Finally rooted. The initial enumeration was hard, but after finding the right file the rest was straight forward. I really liked that ff***g exploit, never seen such a beautiful exploit before!

Finally rooted. What a ride!

User was torturous and fun at the same time. Learned a lot on the way. Baby steps with a lot of enumeration and constantly combining information that you found previously. Every step felt like a victory.

That one exploit was some black magic indeed! Unfortunately I had some trouble reading the credits I found, and stupidly overlooked a simple fix. Thanks to @clubby789 for giving me a nudge!

Root was really easy once I got on the right path, but very fun and satisfying. Unfortunately somebody had rewritten an important file, so it took me some extra time to get on the right track.

Great box @MrR3boot - thank you for the adventure!

@kattekebab said:
Finally rooted. What a ride!

User was torturous and fun at the same time. Learned a lot on the way. Baby steps with a lot of enumeration and constantly combining information that you found previously. Every step felt like a victory.

That one exploit was some black magic indeed! Unfortunately I had some trouble reading the credits I found, and stupidly overlooked a simple fix. Thanks to @clubby789 for giving me a nudge!

Root was really easy once I got on the right path, but very fun and satisfying. Unfortunately somebody had rewritten an important file, so it took me some extra time to get on the right track.

Great box @MrR3boot - thank you for the adventure!

Glad you enjoyed my game! Well Done

Rooted.
Pretty awesome box I must say! Learnt a lot. 9/10!

PM is open for anything on the box.

Hello!
I’m stuck on uploading part. Could anyone help me a bit?
Thanks!

This was difficult and fun! The movie deserves an Oscar! Great box @MrR3boot thanks!

Found upload page, tried diff extensions of files, bit confused on how to find the path of the uploaded file, appreciate some push?

ROOTED root@player:~# whoami Hmmm… Really Nice Machine

I must admit, really hard but interesting machine for me, learnt numerous things with this one. SO REALISTIC !!!

Initial Foothold: Dont get fooled by the forbidden gates, take out directories, try getting all the subdomains, etc. Then go ahead and look sources to find something weird.

User: Make a note of what files were mentioned during your initial enum and which of them you were not able to access, or maybe shown some errors.

Root: Standard linux priv esc technique, 007 out running processes, detect the interesting ones and exploit…

Open to DM if anyone needs help :slight_smile:

Hi,
I have been able to comeback to the C****d d** repository and got a “double” hash. No luck with easy dictonary attack. Knowing that brute force is not needed for this machine I’m wondering if I’m chasing a rabbit.
Should I try to crack the hash or I’m lost again?
Thanks,
Victor

Just got user, so far this is my favorite box, really liked the .a** part.

Hello guys! 've been making first steps in pen craft. Could somebody please make some things out clear for me in PM, have several questions, would appreciate it much. Thanks in advance =-)

Finally finished player. Great machine.

Well done everyone. Hope machine taught you one/two things. Here is my official writeup of the box HackTheBox/Boxes/Player at master · MrR3boot/HackTheBox · GitHub

Type your comment> @MrR3boot said:

Well done everyone. Hope machine taught you one/two things. Here is my official writeup of the box https://github.com/MrR3boot/HackTheBox/tree/master/Boxes/Player

Awesome writeup. Hands down one of the best boxes in HTB!

Totally agree with @zard - this was a fun, engaging and educational box.

@MrR3boot creates some amazing boxes here. I look forward to the next one.

This was an awesome box, thanks @MrR3boot !

I sadly ran out of steam last night without realizing I already had permissions for both root methods (RIP points), but I still wanted to pop in and say I really enjoyed this box.

Being able to discover things slightly out of order, figuring out how/when each discovery mattered, and finding slightly varied solutions to some of the steps (upload, dev, root) made the journey feel a lot more organic than it would have otherwise.

Thanks @MrR3boot!